Fake Russian company websites ran a nine-year scam on foreign buyers

Fraudsters cloned real Russian fertilizer and petrochemical firms, then pocketed advance payments from international customers.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
Photoreal news-editorial 16:9 image of a dimly lit warehouse filled with rows of electronic components and circuit boards in unmarked boxes, harsh fluorescent o
Share

Key points

  • Researchers at Russian security firm F6 uncovered a fraud operation that ran for more than nine years by copying the websites of well-known Russian companies.
  • The fake sites impersonated fertilizer makers, petrochemical producers and other industrial suppliers to lure foreign buyers.
  • Victims were tricked into wiring advance payments to bank accounts controlled by the scammers.
  • The campaign targeted international firms, not Russian consumers, which helped it stay hidden for years.
  • The scheme is classic business-email-and-invoice fraud dressed up with convincing corporate websites.

A fraud ring spent nearly a decade running fake versions of real Russian company websites, using them to trick foreign businesses into wiring money for goods that never arrived. F6, a Russian cybersecurity vendor, published the findings; they were first reported by The Hacker News.

The setup is old-school and effective. Build a website that looks almost identical to a real supplier. Buy a domain name that reads close enough to the real one. Wait for a purchasing manager somewhere in the world to Google the company, land on the clone, and start a conversation. The mark of a good scam is that nothing feels weird until the money's gone.

Who did the scammers pretend to be?

The scammers cloned websites of major Russian industrial firms: fertilizer manufacturers and petrochemical companies. These are exactly the kinds of businesses that international buyers reach out to cold, often across language barriers and time zones, which is what makes the impersonation work.

F6 says the operation ran for over nine years. That's not a smash-and-grab. It's a small business.

How did the fraud actually work?

A foreign buyer would find the fake site, contact what they thought was the sales team, negotiate a bulk order, and be sent an invoice asking for an advance payment. The money went into accounts controlled by the criminals. No fertilizer, no petrochemicals, no refund.

The failure mode here is entirely human and procedural. There's no clever malware in this story; zero-days, meaning secret software flaws, don't feature. The whole thing runs on a convincing logo, a plausible email address, and a buyer who didn't pick up the phone to verify the bank details against a known contact at the real company.

Detail What F6 found
Duration More than 9 years
Sectors impersonated Fertilizer, petrochemical, industrial suppliers
Target victims International companies buying from Russia
Method Cloned websites plus advance-payment invoices
Attribution Not publicly named by F6

Why did this go on so long?

Because the victims were abroad and the impersonated brands were Russian, nobody in either jurisdiction had strong incentive to shut it down. Cross-border invoice fraud is notoriously hard to prosecute: buyers in one country, sellers' identities stolen in another, bank accounts likely in a third.

Every post-mortem on a case like this says the same thing: domain monitoring by the real companies would have caught the clones early. Most large firms don't watch for lookalike domains registering against their brand, and those that do often check only the obvious typos. We first covered brand impersonation as a live threat on 29 July 2026; it's now the subject of three Threat Vectr stories in the past 90 days.

What should buyers do?

If you're purchasing from an unfamiliar overseas supplier, do two boring things. Verify the bank account by calling a phone number you found independently, not one on the invoice or the website you just landed on. Then check the domain registration date: a supplier claiming decades of trading whose website was registered last spring isn't who they say they are.

Brand-impersonation fraud is a procurement problem before it's a security problem, and it stops the moment somebody insists on a verified phone call.

© 2026 Threat Vectr